Cross-Site Scripting Vulnerability in Empathy by GNOME
CVE-2011-4170

Currently unrated

Key Information:

Vendor

Gnome

Status
Vendor
CVE Published:
23 October 2011

What is CVE-2011-4170?

The vulnerability exists in the theme_adium_append_message function of the Adium theme within libempathy-gtk in Empathy versions 3.2.1 and earlier. It enables remote attackers to exploit crafted aliases (nicknames) in /me events, thereby injecting malicious web scripts or HTML content. Successful exploitation can lead to unauthorized actions performed on behalf of users, causing potential data breaches and disruption.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.